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Sir: 

This Reply Brief is respectfully submitted in response to the Examiner's 
Answer mailed July 3, 2007, and does not include any new or non-admitted 
amendment, or any new or non-admitted affidavit or other evidence, in 
compliance with 37 C.F.R. 41 .41 . Entry and consideration of this Reply Brief 
are requested. 
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I. REAL PARTY IN INTEREST 

The statement of the Real Party in Interest contained in the Appeal 
Brief is correct, as the Examiner affirmed in the Examiner's Answer. 

Accordingly, the Real Party in Interest in this Appeal is Hitachi, Ltd., as 
evidenced by the Assignment filed on February 26, 2002 in Application Serial 
No. 10/046,224, filed January 16, 2002, said application being the subject of 
this Appeal, and recorded on Reel 012624 and Frame 0156. 

II. RELATED APPEALS AND INTERFERENCES 

The statement of the Related Appeals and Interferences contained in 
the Appeal Brief is correct, as the Examiner affirmed in the Examiner's 
Answer. 

Accordingly, there are no other Appeals or Interferences that may 
directly affect, may be directly affected by, or have a bearing on the Board's 
decision in this appeal. 

III. STATUS OF CLAIMS 

The statement of the status of the claims in the Appeal Brief is 
incorrect, as the Examiner affirmed in the Examiner's Answer. The statement 
of the status of the claims in the Examiner's Answer is correct. Accordingly, 
the status of the claims is as follows: 

Claims 23-44 are currently pending. 

Claims 23-44 are being appealed. 
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Claims 23-44 are rejected under 35 USC §1 12, second paragraph as 
being indefinite for failing to particularly point out and distinctly claim the 
subject matter which Appellants regard as their invention; and 

Claims 23-44 are rejected under 35 U.S.C. §1 03(a) as being 
unpatentable over U. S. Patent No. 6,697,488 to Cramer et al. ("Cramer"). 

Accordingly, claims 23-44 constitute the claims on appeal, and all 
stand rejected in the final Office Action of February 7, 2006. A copy of claims 
23-44 is attached as pages 57-72 of the Appeal Brief. 

IV. STATUS OF AMENDMENTS 

The statement of the status of the Amendments after Final rejection 
contained in the Examiner's Answer is correct, with the exception that the 
Examiner did not address the Amendment after Final filed on February 7, 
2007. 

As indicated by the Examiner in the Examiner's Answer, the 
Amendment filed September 7, 2006 has been entered, and as indicated by 
the Amendment after Final initialed by the Examiner on April 18, 2007, the 
Amendment filed February 7, 2007 has been entered. 

Accordingly, the Appendix being submitted with the present Reply Brief 
incorporates the amendments to claims 23-44, which were filed on February 
7, 2007. No other amendments were filed after final rejection. 

V. SUMMARY OF THE CLAIMED SUBJECT MATTER 

The statement of the summary of the claimed subject matter contained 
in the Appeal Brief is correct, as the Examiner affirmed in the Examiner's 
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Answer. 

Accordingly, the summary of the invention is included on pages 3-15 of 
the Appeal Brief. 

VI. GROUNDS OF REJECTION TO BE REVIEWED ON APPEAL 

The statement of the grounds of rejection to be reviewed on appeal 
contained in the Appeal Brief is incorrect, as the Examiner affirmed in the 
Examiner's Answer. The statement of the grounds for rejection to be 
reviewed on appeal contained in the Examiner's Answer is correct. 

Accordingly, the statement of the grounds of rejection to be reviewed 
on appeal is as follows: 

Whether claims 23-44 are indefinite under 35 USC §112, second 
paragraph; and 

Whether claims 23-44 are obvious over Cramer under 35 USC 
§1 03(a). 

VII. ARGUMENT 

Appellants make the following response to the various arguments 
made by the Examiner. 

A. 35 USC §1 1 2, second paragraph rejection of claims 23-44 

As a preliminary matter, the Examiner indicates on page 2 of the 
Examiner's Answer, under the Status of Claims heading, that claims 23-44 
are rejected under 35 U.S.C. §1 12, second paragraph. However, on page 4-5 
of the Examiner's Answer, the Examiner only provides specific rejections for 
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claims 23, 24, 28, 30, 35, 36, 40, and 41 (the independent claims). 
Furthermore, on page 24 of the Examiner's Answer, under the Response to 
Argument heading, the Examiner refers to the rejection of claims 25-27, 29, 
31-34, 37-39, and 42-44. Therefore, it appears that the Examiner intended to 
indicate that the remaining claims 25-27, 29, 31-34, 37-39, and 42-44 inherit 
the deficiencies of their respective independent claims. 

With regard to the rejection of claims 23-44, the Examiner indicates on 
page 25 that "A clear definition of the variables would overcome this 112 
rejection", and further indicates that "Similar argument applies to the 
remaining independent claims." 

In response to the Examiner, Appellants submit that the elements 
referred to by the Examiner are well known to one of ordinary skill in the art, 
and do not require any further definition. Nonetheless, Appellants respectfully 
invite the Board to provide a statement of how to overcome this rejection. 

/. Claims 23, 28, 35, and 40 

Claims 23, 28, 35, and 40 are rejected as failing to provide sufficient 
antecedent basis for "a^ || ci2 < q". In the Response to Argument section on 
page 24-25 of the Examiner's Answer, the Examiner indicates that Appellants 
failed to address the insufficient antecedent basis issues raised in the 
previous office action. 

In response to the Examiner, Appellants submit that this rejection is 
traversed. With regard to claim 23, for example, Appellants submit that the 
first recitation of Qi || Q2< q appears in line 14, and is not preceded by "the". 
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Accordingly, there is sufficient antecedent basis for this limitation. Similar 
arguments apply for the remaining claims 28, 35 and 40. 

Furthermore, Appellants submit that the elements of ai || a 2 < q are well 
known to one of ordinary skill in the art, and do not require any further 
definition. However, Appellants respectfully invite the Board to provide a 
statement of how to overcome this rejection. 

//. Claims 24, 40 and 41 

Claims 24, 40 and 41 are rejected as failing to provide sufficient 
antecedent basis for "ciphertext and by using the secret key, a'i, a' 2 , m"\ In 
the Response to Argument section on page 24-25 of the Examiner's Answer, 
the Examiner indicates that Appellants failed to address the insufficient 
antecedent basis issues raised in the previous office action. 

In response to the Examiner, Appellants submit that this rejection is 
traversed. Appellants submit that the Examiner is improperly combining 
individual features of claims 24, 40 and 41 to make a single feature. 
However, the "ciphertext", the "secret key" and "a'i, a' 2 , m'" should be treated 
separately. 

With regard to claim 24, for example, Appellants submit that the first 
recitation "ciphertext" occurs in line 16 (i.e., "transmitting (ui, u 2 , e, v) as a 
ciphertext"). Similar arguments apply to claims 40 and 41 . 

With further regard to claim 24, for example, Appellants submit that the 
first recitation of "a secret key" occurs in line 3. Accordingly, there is sufficient 
antecedent basis for this limitation. Similar arguments apply to claims 40 and 
41. 
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With even further regard to claim 24, for example, Appellants submit 
that the first recitation of "a'i, a' 2> m'" occurs in line 18, and is not preceded by 
"the". Accordingly, there is sufficient antecedent basis for this limitation. 
Similar arguments apply to claims 40 and 41 . 

Furthermore, Appellants submit that the elements of a'i, a' 2 , m' are well 
known to one of ordinary skill in the art, and do not require any further 
definition. However, Appellants respectfully invite the Board to provide a 
statement of how to overcome this rejection. 

///. Claim 30 

Claim 30 is rejected as failing to provide proper antecedent basis for 
the following limitation: 

m = D K . (C) 

In the Response to Argument section on pages 24-25 of the Examiner's 
Answer, the Examiner indicates that Appellants failed to address the 
insufficient antecedent basis issues raised in the previous office action. 

In response to the Examiner, Appellants submit that this rejection is 
traversed. Appellants submit that the first recitation of this limitation occurs in 
line 29, and is not preceded by "the". Accordingly, there is sufficient 
antecedent basis for this limitation. 

Furthermore, Appellants submit that the elements of the above- 
identified limitation are well known to one of ordinary skill in the art, and do not 
require any further definition. However, Appellants respectfully invite the 
Board to provide a statement of how to overcome this rejection. 
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iv. Claim 36 

Claim 36 is rejected as failing to provide proper antecedent basis for 
"transmitting the ciphertext (ui, u 2 , v, C)". In the Response to Argument 
section on page 24-25 of the Examiner's Answer, the Examiner indicates that 
Appellants failed to address the insufficient antecedent basis issues raised in 
the previous office action. 

In response to the Examiner, Appellants submit that this rejection is 
traversed. Appellants submit that the first recitation of this limitation occurs in 
line 16, and is not preceded by "the". Accordingly, there is sufficient 
antecedent basis for this limitation. 

Furthermore, Appellants submit that the elements of the above- 
identified limitation are well known to one of ordinary skill in the art, and do not 
require any further definition. However, Appellants respectfully invite the 
Board to provide a statement of how to overcome this rejection. 

v. Claims 28, 40 and 41 

Claims 28, 40 and 41 are rejected as failing to provide proper 
antecedent basis for the following limitation: 

". . . = D sk (e)" 

In the Response to Argument section on page 24-25 of the Examiner's 
Answer, the Examiner indicates that Appellants failed to address the 
insufficient antecedent basis issues raised in the previous office action. 
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In response to the Examiner, Appellants submit that this rejection is 
traversed. Regarding claim 28, Appellants submit that the above-identified 
limitation is not recited in claim 28. With regard to claims 40 and 41 , 
Appellants submit that the first recitation of this limitation occurs in lines 28 
and 22, respectively, and is not preceded by "the". Accordingly, there is 
sufficient antecedent basis for this limitation. 

Furthermore, Appellants submit that the elements of the above- 
identified limitation are well known to one of ordinary skill in the art, and do not 
require any further definition. However, Appellants respectfully invite the 
Board to provide a statement of how to overcome this rejection. 

Accordingly, Appellants submit that each of claims 23-44 are definite 
and fully comply with the requirements of 35 USC §112, second paragraph. 
Therefore, reconsideration and withdrawal of the 35 USC §112, second 
paragraph rejection of claims 23-44 are respectfully requested. 

B. 35 USC §1 03(a) rejection of claims 23-44 
/. Independent Claim 23 

One feature of the present invention, as recited in independent claim 
23, includes a key generation step of generating a secret key and a public 
key. The secret key includes xi, x 2 , yn, yi2, y2i, yz2, and z. The public key 
includes elements di and d 2 . The element di relates to the elements yn and 
y 12 of the secret key, and the element d 2 relates to the elements y 2 i and y 22 of 
the secret key. Cramer does not disclose this feature. 
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In response to Appellants' arguments that Cramer does not teach or 
suggest where the public key includes elements di and d 2 , the Examiner 
asserts on page 26 of the Examiner's Answer that Cramer teaches "d" (citing 
section V, column 9), and thus "d" can change and varies. 

In response to the Examiner's arguments, Appellants note that in 
column 9, lines 57-58, Cramer discloses where the group element d is 

changed by di dx, where 1< i < k. However, Cramer is silent as to the 

value of k used to implement the Cramer system. The present invention uses 
elements di and d 2 , which corresponds to k=2, and Appellants submit that in 
actual implementation of Cramer, k is larger than or equal to 4. 

With regard to the actual implementation of Cramer, Appellants submit 
that although Cramer is silent as to the value of k used to implement the 
Cramer system, the article A Practical Public Key Cryptosystem Provably 
Secure against Adaptive Chosen Ciphertext Attack, by Cramer, et al. 
("Cramer Article") provides the value of k used to implement the Cramer 
system. The Cramer Article was submitted in an Information Disclosure 
Statement (IDS) on February 7, 2007, and was considered by the Examiner 
on April 20, 2007. 

As described on page 15 under section 5.3, the Cramer Article 
discusses a hypothetical situation where if strings needed to hash in an 
original scheme are of the form (a-i, . . . , an), where 0 < a\ < p. The input to 
the hash function is ui, u 2 , e € G, and is expressed by the bit series Ut || u 2 || 
e (where || means concatenation). When the bit series is expressed using a„ 



10 



U. S. Patent Application No. 10/046,224 

where 0 < a, < q, it can be expressed as ai |j . . . || a k . The minimum k is 
selected. 

With further reference to the Cramer Article, regarding security, the 
prime number p should have at least 1024 bits in the multiplicative group. If p 
has 1024 bits, the prime number q becomes maximum when q satisfies p - 1 
= 2q, and q has 1023 bits, ui, u 2 and e have 1024 bits, respectively. When ui 
|| u 2 || e is expressed using concatenation of ai, which has less than or equal 
to 1023 bits, the concatenation number k will be at least 4. 

When Ui = gi r (i = 1 , 2) is calculated for the encryption, r has 1023 bits 
and the exponent number is large. Accordingly, the efficiency of the 
calculation is poor. In the Cramer Article, when the hash function is not used, 
v is calculated using the expression on page 15 (sixth line from the bottom). If 
q is a small number, k becomes large, and the calculation amount of v also 
becomes large. 

In response to Appellants' arguments that in the present invention, k is 
kept small, the Examiner asserts on page 26 of the Examiner's Answer that 
features upon which Appellants rely upon (i.e., k is 2 and kept small) are not 
recited in the rejected claims. 

In response to the Examiner's arguments, and as previously discussed, 
the present invention uses elements di and dz, which corresponds to k=2. 
The correspondence between d and k is well known to one of ordinary skill in 
the art. Therefore, it is not necessary to include k in the claims. 
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In response to Appellants' arguments that Cramer does not teach or 
suggest where the secret key includes yn, yi 2 , y2i, y22, the Examiner asserts 
on page 26 of the Examiner's Answer that Cramer expressly claims "choosing 
at least a first, second, and third . . ." (citing claim 1). 

In response the Examiner's arguments, Appellants direct the 
Examiner's attention to the context and entirety of the language used in claim 
1 of Cramer. The claim language of Cramer recites "choosing at least a first, 
second, and third exponent-number (x 1s x 2 , z) as part of a private key." As 
described in column 7, lines 11-19, Cramer discloses where a first exponent- 
number xi, a second exponent-number x 2 , a third exponent-number z, a fourth 
exponent-number y^, and a fifth exponent-number y 2 , are chosen at random 
for the private key. As such, Cramer discloses the use of elements yi and y 2 , 
and the "choosing at least a first, second, and third" language referred to in 
claim 1 of Cramer does not refer to "choosing at least a first, second, and 
third" of elements yi and y 2 . Unlike Cramer, in the present invention, the 
secret key includes yn, yi 2 , y 2 i, y 22 . Cramer does not teach or suggest the 
additional elements of the claimed invention, and the claim language of 
Cramer cited by the Examiner does not refer to the additional elements in the 
group yn, yi 2 , y 2 i, y 22 of the present invention. 

Furthermore, as described in column 9, lines 65-67, Cramer describes 
where, in order to achieve security against lunch-time attacks, "one can 
simplify the above-described basic scheme" by omitting d, yi and y 2 . As such, 
Cramer teaches away from adding additional elements, so as to include both 
elements di and d 2 in the public key, and each of elements yn, yi 2 , y 2 i, y 22 in 
the secret key. Therefore, contrary to the Examiner's assertions, it would not 
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be obvious to modify Cramer to add the additional elements, so as to achieve 
the present invention. 

In response to Appellants' arguments that Cramer teaches away from 
adding additional elements to obtain the present invention (i.e., yn, yi 2 , y 2 i, 
y22), the Examiner asserts on pages 29-30 (with reference to the rejection of 
claim 30) that Cramer suggests the use of more elements (citing claims 1,11 
and 20). Specifically, the Examiner asserts that the language "choosing at 
least" implies that more elements may be added. 

In response to the Examiner's arguments, Appellants direct the 
Examiner's attention to the specific language in claims 1,11 and 20 that 
follows "choosing at least". There is no disclosure in claims 1 , 1 1 or 20 of 
choosing at least elements including the element y. The "choosing at least" 
phrase precedes x,, x 2 , Z, g 1( g 2 , etc., but does not precede the element y. 
Therefore, contrary to the Examiner's assertions, Cramer does teach away 
from adding the additional elements to obtain yn, yi 2 , y 2 i, y 22 , as in the 
present invention. 

Therefore, Cramer fails to teach or suggest " a key generation step of 
generating a secret-kev: 

• xi, x 2) yn, 2/12, !/2i, 2/22, z e Z q 
and a public-key: 

• G,G' : finite (multiplicative) group G C G' 

• q : prime number (the order of G) 

• 9u92 e G 

•c = 9i Xl 92 x \ di = 9i Vll 92 Vl3 , d 2 = 5i Ml 52 y ", h = gi z , 

• 7r : X\ x Xi x M — > G' : one-to-one mapping 

• 7T- 1 : Im(7r) — > X x x X 2 x M 
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where the group G is a partial group of the group G'. Xi and X? are an infinite 
set of positive integers which satisfy: 

Q\\\oc2<q (Vc*i € X\, Vc*2 € -X" 2 ) 

where M is a plaintext space " as recited in independent claim 23. 

Another feature of the present invention, as recited in independent 
claim 23, includes a ciphertext generation and transmission step of selecting 
random numbers for a plaintext m, calculating ui, u 2 , e, and v, where: 

e = w (a u a 2 , m) h r , and v = gf 1 d d, ar d 2 mr . 
Cramer does not disclose this feature. 

In response to Appellants' arguments that Cramer fails to teach or 
suggest e = n (a if a 2 , m) h r and v = g° 1 d d° r d 2 mr , the Examiner asserts on 
page 27 of the Examiner's Answer that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). The Examiner further 
asserts that adding, subtracting, raising to the power, or performing a mod 
operation without clearly defining what the numbers are do not patentably 
distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
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features of the present invention, and is clearly different from the claimed 
invention. 

For example, the verification cipher-number v, as calculated in Cramer 
(i.e., v = c r d ra ) is quite different from v, as calculated in the present invention 
(i.e., v = gf 1 d d° r d 2 mr ), and the Examiner has not provided any explanation 
as to why one of ordinary skill in the art would be motivated to modify Cramer 
to obtain this feature. In the present invention, the calculation of v is improved 
and k can be a small number. This is quite different from Cramer, where as 
described in the Cramer Article, k is equal to or greater than 4. In the present 
invention, r can be set small, and the encryption calculation can be efficiently 
performed. 

By way of further example, as shown in column 8, line 5, Cramer 
discloses where the encryption cipher-number e is calculated according to the 
following formula: e = h r m. This is quite different from the present invention, 
where e = tt (a 1t a 2 , m) h r , and the Examiner has not provided any explanation 
as to why one of ordinary skill in the art would be motivated to modify Cramer 
to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers Oi g Xi. op pXp, rg Zg for a 
plaintext m (m p M). calculating: 

tJ-\=9i r , U2 = g2 r , e = TT(ai,a2,m)h r , v = gi ai c r di° r d 2 mr 

where a = ai II o?. and transmitting (ui. u?. e. v) as a ciphertext " as recited in 
independent claim 23. 
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Yet another feature of the present invention, as recited in independent 
claim 23, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step is performed of outputting m' as the 
deciphered results, if the following is satisfied: 

5i a' lni xi+a'vii+m'v 2 i tt2 i 2 +a'y l 3+m'v3 2 _ y 

If the above condition is not satisfied, then a step is performed of outputting as 
the decipher results the effect that the received ciphertext is rejected. Cramer 
does not disclose this feature. 

In response to Appellants' arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). The Examiner further 
asserts that adding, subtracting, raising to the power, or performing a mod 
operation without clearly defining what the numbers are do not patentably 
distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are weir known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 
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For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: m x1+y1a if 2+y2a = v. The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciohertext and bv using the 
secret kev. oV a'?, m' (a'i g Xi. a'^X?. mV lvn which satisfy: 

n(a\, at2,m') = e/u\ z 
and if the following is satisfied: 

g l a 'iu\ Xl + a ' Vil+m ' V21 U2 Xi+ayi2+m ' v ' >7 = v 

outputtino m' as the deciphered results (where a' = a'i II oV). wh ereas if not 
satisfied, outouttino as the decipher results the effect that the received 
ciphertext is rejected " as recited in independent claim 23. 

//. Independent Claim 24 

One feature of the present invention, as recited in independent claim 
24, includes a key generation step of generating a secret key and a public 
key. The secret key includes xi, x 2 , yn, yi 2 , y2i, y22, and z. The public key 
includes elements di and d 2 , and the elements c, di, d 2 , and h are calculated 
using modulo arithmetic. The element di relates to the elements yn and yi 2 
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of the secret key, and the element 62 relates to the elements y2i and y22 of the 
secret key. Cramer does not disclose this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest where the public key includes elements di and d 2 , the Examiner 
asserts on page 26 of the Examiner's Answer that Cramer teaches "d" (citing 
section V, column 9), and thus "d" can change and varies. 

In response to the Examiner's arguments, Appellants note that in 
column 9, lines 57-58, Cramer discloses where the group element d is 

changed by di d k , where 1< i < k. However, Cramer is silent as to the 

value of k used to implement the Cramer system. The present invention uses 
elements di and d2, which corresponds to k=2, and as previously discussed 
with reference to the Cramer Article, Appellants submit that in the actual 
implementation of Cramer, k is larger than or equal to 4. 

In response to Appellants' arguments that Cramer does not teach or 
suggest where the secret key includes yn, yi 2 , y 2 i, y 2 2> the Examiner asserts 
on page 27 of the Examiner's Answer that Cramer expressly claims "choosing 
at least a first, second, and third . . ." (citing claim 1). 

In response the Examiner's arguments, Appellants direct the 
Examiner's attention to the context and entirety of the language used in claim 
1 of Cramer. The claim language of Cramer recites "choosing at least a first, 
second, and third exponent-number (x 1f x 2 , z) as part of a private key." As 
described in column 7, lines 11-19, Cramer discloses where a first exponent- 
number x u a second exponent-number x 2 , a third exponent-number z, a fourth 
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exponent-number yi, and a fifth exponent-number y 2 , are chosen at random 
for the private key. As such, Cramer discloses the use of elements yi and y 2 , 
and the "choosing at least a first, second, and third" language referred to in 
claim 1 of Cramer does not refer to "choosing at least a first, second, and 
third" of elements yi and y 2 . Unlike Cramer, in the present invention, the 
secret key includes yn, yi 2 , y2i, y22- Cramer does not teach or suggest the 
additional elements of the claimed invention, and the claim language of 
Cramer cited by the Examiner does not refer to the additional elements in the 
group yn, yi 2 , y 2 i, y 22 of the present invention. 

Furthermore, as previously discussed, Cramer teaches away from 
adding additional elements to obtain the present invention. As described in 
column 9, lines 65-67, Cramer describes where, in order to achieve security 
against lunch-time attacks, "one can simplify the above-described basic 
scheme" by omitting d, yi and y 2 . As such, Cramer teaches away from adding 
additional elements, so as to include both elements di and d 2 in the public 
key, and each of elements yn, yi 2 , y 2 i, y^ in the secret key. Therefore, 
contrary to the Examiner's assertions, it would not be obvious to modify 
Cramer to add the additional elements, so as to achieve the present invention. 

In response to Appellants' argument that Cramer teaches away from 
adding additional elements to obtain the present invention (i.e., yn, yi 2 , y 2 i, 
y^), the Examiner asserts on pages 29-30 (with reference to the rejection of 
claim 30) that Cramer suggests the use of more elements (citing claims 1,11 
and 20). Specifically, the Examiner asserts that the language "choosing at 
least" implies that more elements may be added. 
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In response to the Examiner's arguments, Appellants direct the 
Examiner's attention to the specific language in claims 1,11 and 20 that 
follows "choosing at least". There is no disclosure in claims 1 , 1 1 or 20 of 
choosing at least elements including the element y. The "choosing at least" 
phrase precedes Xi, x 2 , Z, g u g 2 , etc., but does not precede the element y. 
Therefore, contrary to the Examiner's assertions, Cramer does teach away 
from adding the additional elements to obtain y 11( y 12 , y 2 i, y22, as in the 
present invention. 

In response to Appellants' arguments that Cramer does not teach or 
suggest the use of modulo arithmetic in the equations used to calculate c, di, 
d 2 , and h, the Examiner does not provide any arguments for claim 24. 
However, as best can be determined, with reference to the Examiner's 
response regarding claim 23 on page 27 of the Examiner's Answer, it appears 
that the Examiner's position is that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). Specifically, the 
Examiner asserts that adding, subtracting, raising to the power, or performing 
a mod operation without clearly defining what the numbers are do not 
patentably distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
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features of the present invention, and is clearly different from the claimed 
invention. 

For example, column 7, lines 25-27 of Cramer describes where the 
public key is "represented by the numbers gi, g 2 , c, d, and h", and column 7, 
line 25 shows the calculations used to derive the numbers c, d and h. As 
shown, Cramer does not disclose the use of modulo arithmetic in the 
equations used to calculate c, d and h. This is quite different from the present 
invention, where the step of generating a public key includes the elements c, 
di, d 2 , and h, which are calculated using modulo arithmetic. Accordingly, 
Cramer does not teach generating a public key in the manner claimed, and 
the Examiner has not provided any explanation as to why one of ordinary skill 
in the art would be motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a kev generation step of 
generating a secret-key: 

• xi,x 2 ,yn,y\2,y2i,y22,z e Z q 

and a public-key: 

• P. 9 : prime number (q is a prime factor of p-1 ) 

• 9i,92 e Z p : ordp(gi) = ord p (p 2 ) = Q 

• c = gi Xl g 2 X3 mod p, d\ — ffi vn ff2 V12 mod p, d 2 = 9\ V2l 92 V22 mod p, h = gi z mod p, 

• fci,fc2,*3 : positive constant (I0 fc > +fc > < q, 10 k > < q, 10 fc ' +fc ' +fc3 < p) 

" as recited in independent claim 24. 
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Another feature of the present invention, as recited in independent 
claim 24, includes a ciphertext generation and transmission step of selecting 
random numbers for a plaintext m, calculating u 1t u 2 , e, and v, where: 

Ui = g\ T mod p, u-z = g 2 r mod p, e = m h r mod p, v = gi Ql c r di ar d 2 rnr mod p 

Cramer does not disclose this feature. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 25 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used instead of the 
hash function. The calculation of v is unique to the present invention. 
Specifically, the verification cipher-number v, as calculated in Cramer (i.e., v = 
c r d a ) and which uses the hash value a, is quite different from v, as calculated 
in the present invention (i.e., v = g* 1 d di ar d 2 mr mod p), and the Examiner 
has not provided any explanation as to why one of ordinary skill in the art 
would be motivated to modify Cramer to obtain this feature. Furthermore, 
even if Cramer omits the hash function from the equation, Cramer still does 
not teach the unique calculation of v, as in the present invention. 
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In response to Appellants' arguments that Cramer does not disclose 
the use of modulo arithmetic in the equations used to calculate ui, u 2 , e, and 
v, the Examiner does not provide any arguments for claim 24. However, as 
best can be determined, with reference to the Examiner's response regarding 
claim 23 on page 27 of the Examiner's Answer, it appears that the Examiner's 
position is that Cramer expressly teaches performing calculations with the 
specific elements to obtain keys and decrypted data (citing claims 1 and 1 1 ; 
and column 1 1 , lines 43-60). Specifically, the Examiner asserts that adding, 
subtracting, raising to the power, or performing a mod operation without 
clearly defining what the numbers are do not patentably distinguish the 
present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. Specifically, Cramer is quite different from the present invention, 
where the step of generating a public key includes where the elements Ui, u 2 , 
e, and v are calculated using modulo arithmetic. Accordingly, Cramer does 
not teach generating a public key in the manner claimed, and the Examiner 
has not provided any explanation as to why one of ordinary skill in the art 
would be motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers a = ai II a? (la-il = ki. \a?\ 
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= ko) for a plaintext m (Iml = k.-^ where Ixl is the number of digits of x). 
calculating: 

m = a \\K 

selecting a random number r ^ Zo, calculating: 
ui=pi r modp, U2 = 92 mod p, e = m h r mod p, v = gi ai c r di ar d 2 Tnr mod p 

and transmitting (u h u?. e. v) as a ciphertext " as recited in independent 
claim 24. 

Yet another feature of the present invention, as recited in independent 
claim 24, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step is performed of outputting m' as the 
deciphered results, if the following is satisfied: 

g l a 'iui xl+Q ' vll+m ' y21 U2 x * +Q ' yi2+m ' V2 * = v (mod p) 

If the above condition is not satisfied, then a step is performed of outputting, 
as the decipher results, the effect that the received ciphertext is rejected. 
Cramer does not disclose this feature. 

In response to Appellants arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner does not provide any 
arguments for claim 24. However, as best can be determined, with reference 
to the Examiner's response regarding claim 23 on page 27 of the Examiner's 
Answer, it appears that the Examiner's position is that Cramer expressly 
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teaches performing calculations with the specific elements to obtain keys and 
decrypted data (citing claims 1 and 11; and column 11, lines 43-60). The 
Examiner further asserts that adding, subtracting, raising to the power, or 
performing a mod operation without clearly defining what the numbers are do 
not patentably distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: ui xUy1a \f 2+y2a = v. The condition [1 ] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciohertext and bv using the 
secret kev. aV o'?. m' (laM = ki. Ia'?l = k?. Im 'l = which satisfy: 

aiHa'allm' = e/ui z mod p 
and if the following is satisfied: 

Si a/l ui xl+a ' vn+m ' OT1 U2 xa+Q ' yi2+m ' y " = v (mod p) 
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outputting m' as the deciphered results (where a' = a'i [| a' 2 ), whereas if not 
satisfied, outputting as the decipher results the effect that the received 
ciphertext is rejected " as recited in independent claim 24. 

///. Independent Claim 28 

One feature of the present invention, as recited in independent claim 
28, includes a key generation step of generating a secret key and a public 
key. The secret key includes xi, x 2 , yn, yi2, y2i, y22, and z. The public key 
includes elements di and d 2 . The element di relates to the elements yn and 
yi 2 of the secret key, and the element d 2 relates to the elements y 2 i and y 22 of 
the secret key. Cramer does not disclose this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest where the public key includes elements di and d 2 , the Examiner 
asserts on page 26 of the Examiner's Answer that Cramer teaches "d" (citing 
section V, column 9), and thus "d" can change and varies. 

In response to the Examiner's arguments, Appellants note that in 
column 9, lines 57-58, Cramer discloses where the group element d is 

changed by di d k , where 1< i < k. However, Cramer is silent as to the 

value of k used to implement the Cramer system. The present invention uses 
elements di and d 2 , which corresponds to k=2, and as previously discussed 
with reference to the Cramer Article, Appellants submit that in the actual 
implementation of Cramer, k is larger than or equal to 4. 
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In response to Appellants' arguments that Cramer does not teach or 
suggest where the secret key includes yn, yi 2 , y2i, y2 2 , the Examiner asserts 
on page 28 of the Examiner's answer that Cramer expressly claims "choosing 
at least a first, second, and third . . ." (citing claim 1). 

In response the Examiner's arguments, Appellants direct the 
Examiner's attention to the context and entirety of the language used in claim 
1 of Cramer. The claim language of Cramer recites "choosing at least a first, 
second, and third exponent-number (xi, x 2 , z) as part of a private key." For 
example, as previously discussed, column 7, lines 11-19 of Cramer describes 
where a first exponent-number xi, a second exponent-number x 2 , a third 
exponent-number Z, a fourth exponent-number y^ and a fifth exponent- 
number y 2 , are chosen at random for the private key. As such, Cramer 
discloses the use of elements yi and y 2 , and the "choosing at least a first, 
second, and third" language referred to in claim 1 of Cramer does not refer to 
"choosing at least a first, second, and third" of elements yi and y 2 . Unlike 
Cramer, in the present invention, the secret key includes yn, yi 2 , y 2 n, y 22 . 
Cramer does not teach or suggest the additional elements of the claimed 
invention. 

Furthermore, as previously discussed, Cramer teaches away from 
adding additional elements to obtain the present invention. As described in 
column 9, lines 65-67, Cramer describes where, in order to achieve security 
against lunch-time attacks, "one can simplify the above-described basic 
scheme" by omitting d, yi and y 2 . As such, Cramer teaches away from adding 
additional elements, so as to include both elements di and d 2 in the public 
key, and each of elements yn, yi 2 , y 2 i, y^ in the secret key. Therefore, 
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contrary to the Examiner's assertions, it would not be obvious to modify 
Cramer to add the additional elements, so as to achieve the present invention. 

In response to Appellants argument that Cramer teaches away from 
adding additional elements to obtain the present invention (i.e., yn, yi 2 , y2i, 
y 2 2), the Examiner asserts on pages 28-29 that Cramer suggests the use of 
more elements (citing claims 1,11 and 20). Specifically, the Examiner 
asserts that the language "choosing at least" implies that more elements may 
be added. 

In response to the Examiner's arguments, Appellants direct the 
Examiner's attention to the specific language in claims 1,11 and 20 that 
follows "choosing at least". There is no disclosure in claims 1 , 11 or 20 of 
choosing at least elements including the element y. The "choosing at least" 
phrase precedes x 1( x 2 , Z, g 1f g 2 , etc., but does not precede the element y. 
Therefore, contrary to the Examiner's assertions, Cramer does teach away 
from adding the additional elements to obtain yn, yi 2 , y 2 i, y 22 , as in the 
present invention. 

Therefore, Cramer fails to teach or suggest " a kev generation step of 
generating a secret-kev: 

• XI, X2,yil,yi2, 1/21, 2/22,2 e z, 

and a public-kev: 
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• G,G' : finite (multiplicative) group G C G' 

• q : prime number (the order of G) 

• 9i , 92 € G 

•c = 9i Xl g 2 X2 , di = 9i vu 92 Vl2 , d 2 = 9i V21 g 2 V22 , h = gS, 

• 7r : X\ x Xi x M — *■ G' : one-to-one mapping 

• 7T" 1 : Im(7r) — ► X x x X 2 x M 

• E : symmetric encipher function 

where the group G is a partial group of the group G'. Xi and X? are an infinite 
set of positive integers which satisfy: 

ai||a:2 < q (Vai € X\, Vq2 € X 2 ) 

where M is a key space " as recited in independent claim 28 of the present 
invention. 

Another feature of the present invention, as recited in independent 
claim 28, includes a ciphertext generation and transmission step of selecting 
random numbers for key data K, calculating Ui, u 2 , e, and v, where: 

e = n(a u a 2 , K)h r , and v = gf 1 c r d 2 Kr . 
Cramer does not disclose this feature. 

In response to Appellants arguments that Cramer fails to teach or 
suggest e = tt (a h a 2 , K) h r and v = g° 1 d d° r d 2 Kr , the Examiner asserts 
on page 27 of the Examiner's Answer (with reference to the rejection of claim 
23) that Cramer expressly teaches performing calculations with the specific 
elements to obtain keys and decrypted data (citing claims 1 and 1 1 ; and 
column 1 1 , lines 43-60). The Examiner further asserts that adding, 
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subtracting, raising to the power, or performing a mod operation without 
clearly defining what the numbers are do not patentably distinguish the 
present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, the verification cipher-number v, as calculated in Cramer 
(i.e., v = c' d ra ) is quite different from v, as calculated in the present invention 
(i.e., v = g° 1 d d° r d 2 Kr ), and the Examiner has not provided any explanation 
as to why one of ordinary skill in the art would be motivated to modify Cramer 
to obtain this feature. In the present invention, the calculation of v is improved 
and k can be a small number. This is quite different from Cramer, where as 
described in the Cramer Article, k is equal to or greater than 4. In the present 
invention, r can be set small, and the encryption calculation can be efficiently 
performed. 

By way of further example, as shown in column 8, line 5, Cramer 
discloses where the encryption cipher-number e is calculated according to the 
following formula: e = h r m. This is quite different from the present invention, 
where e = tt (a u 02, K) h r> and the Examiner has not provided any explanation 
as to why one of ordinary skill in the art would be motivated to modify Cramer 
to obtain this feature. 
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In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 25 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used instead of the 
hash function. That is to say, the calculation of v is unique to the present 
invention. Specifically, the verification cipher-number v, as calculated in 
Cramer (i.e., v = d d a ) is quite different from v, as calculated in the present 
invention (i.e., v = g° 1 d 6° r d 2 Kr ), and the Examiner has not provided any 
explanation as to why one of ordinary skill in the art would be motivated to 
modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers Qi pXl QppXp, r ^Zo for key 
data K(K r M). calculating: 

u\ = 9i r y U2 = 92 r , e = n(on,ct2,K)h r , v = g\ ai c r di ar d 2 Kr 

where o = Qi II o?. generating a ciphertext C of transmission data m by: 

C = E K (m) 
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by using a (symmetric cryptographic function E and kev data K. and 
transmittin g Oh. u ? , e. v. C) as the ciohertext " as recited in independent claim 
28. 

Yet another feature of the present invention, as recited in independent 
claim 28, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step is performed of executing a decipher 
process, if the following is satisfied: 

g l a 'iUi xl+a ' vll+K ' vll U2 X2+a ' Vl3+K ' V23 = V 

If the above condition is not satisfied, then a step is performed of outputting as 
the decipher results the effect that the received ciphertext is rejected. Cramer 
does not disclose this feature. 

In response to Appellants arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer (with regard to the rejection of claim 23) that Cramer 
expressly teaches performing calculations with the specific elements to obtain 
keys and decrypted data (citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). 
The Examiner further asserts that adding, subtracting, raising to the power, or 
performing a mod operation without clearly defining what the numbers are do 
not patentably distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
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whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u r x?+> " a u* 2+y2a = v. The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciphertext and bv using the 
secret key. q'i. q'p. K' (o'i r Xl q'? r X?, K' k M) which satisfy: 

n(a' 1 \\a' 2 \\K') = e/u 1 ' 

and if the following is satisfied: 

g l a 'lU\ xl+a ' vll+K>lni U2 X2+a ' Vi3+K ' V2 ' 1 = V 

where o' = o'i II a'? 

executing a decipher process by: 

m = D K ,{C) 

outputtino deciphered results, whereas if not satisfied, outputtino as the 
decipher results the effect that the received ciphertext is rejected " as recited in 
independent claim 28. 
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iv. Independent Claim 30 

One feature of the present invention, as recited in independent claim 
30, includes a key generation step of generating a secret key and a public 
key. The secret key includes Xi, x 2 , yn, yi 2 , V2^, Y22, and z. The public key 
includes elements d 1 and d 2 . The element di relates to the elements yn and 
yi2 of the secret key, and the element d 2 relates to the elements y 2 i and y 22 of 
the secret key. Cramer does not disclose this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest where the public key includes elements di and d 2 , the Examiner 
asserts on page 26 of the Examiner's Answer that Cramer teaches "di" (citing 
section V, column 9), and thus "d" can change and varies. 

In response to the Examiner's arguments, Appellants note that in 
column 9, lines 57-58, Cramer discloses where the group element d is 
changed by di, . . . , d k , where 1< i < k. However, Cramer is silent as to the 
value of k used to implement the Cramer system. The present invention uses 
elements di and d 2 , which corresponds to k=2, and as previously discussed 
with reference to the Cramer Article, Appellants submit that in the actual 
implementation of Cramer, k is larger than or equal to 4. 

In response to Appellants arguments that Cramer does not teach or 
suggest where the secret key includes yn, yi 2 , y 2 i, y 22 , the Examiner asserts 
that Cramer expressly claims "choosing at least a first, second, and third . . ." 
(citing claim 1). 
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In response the Examiner's arguments, Appellants direct the 
Examiner's attention to the context and entirety of the language used in claim 
1 of Cramer. The claim language of Cramer recites "choosing at least a first, 
second, and third exponent-number (x^ x 2 , z) as part of a private key." As 
described in column 7, lines 11-19, Cramer discloses where a first exponent- 
number xi, a second exponent-number x 2) a third exponent-number z, a fourth 
exponent-number yi, and a fifth exponent-number y 2 , are chosen at random 
for the private key. As such, Cramer discloses the use of elements y^ and y 2 , 
and the "choosing at least a first, second, and third" language referred to in 
claim 1 of Cramer does not refer to "choosing at least a first, second, and 
third" of elements yi and y 2 . Unlike Cramer, in the present invention, the 
secret key includes yn, yi 2 , y 2 i, y22. Cramer does not teach or suggest the 
additional elements of the claimed invention, and the claim language of 
Cramer cited by the Examiner does not refer to the additional elements in the 
group yn, yi 2 , y 2 i, y 22 of the present invention. 

Furthermore, as described in column 9, lines 65-67, Cramer describes 
where, in order to achieve security against lunch-time attacks, "one can 
simplify the above-described basic scheme" by omitting d, y^ and y 2 . As such, 
Cramer teaches away from adding additional elements, so as to include both 
elements di and d 2 in the public key, and each of elements yn, yi 2 , y 2 i, y 22 in 
the secret key. Therefore, contrary to the Examiner's assertions, it would not 
be obvious to modify Cramer to add the additional elements, so as to achieve 
the present invention. 
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In response to Appellants argument that Cramer teaches away from 
adding additional elements to obtain the present invention (i.e., yn, yi 2 , y2i, 
y22), the Examiner asserts on pages 29-30 (with reference to the rejection of 
claim 30) that Cramer suggests the use of more elements (citing claims 1,11 
and 20). Specifically, the Examiner asserts that the language "choosing at 
least" implies that more elements may be added. 

In response to the Examiner's arguments, Appellants direct the 
Examiner's attention to the specific language in claims 1,11 and 20 that 
follows "choosing at least". There is no disclosure in claims 1 , 1 1 or 20 of 
choosing at least elements including the element y. The "choosing at least" 
phrase precedes Xi, x 2 , Z, g lt g 2> etc., but does not precede the element y. 
Therefore, contrary to the Examiner's assertions, Cramer does teach away 
from adding the additional elements to obtain yn, yi 2 , y 2 i, y 22 , as in the 
present invention. 

Therefore, Cramer fails to teach or suggest " a key generation step of 
generating a secret-key: 

• xi, X2,yn,yi2, 2/21, 2/22, z 6 

and a public-key: 

• P,9 '• prime number (q is a prime factor of p-1) 

• 91,92 € Z p : ordp(pi) = ord p (p 2 ) = q 

m c = 0i Xl ff2 X2 mod p, d\ = gi vil 92 y " mod p, d 2 = t/i V21 ff2 v " mod p, h = gi z mod p, 

• Jk1.Jk2.fc3 : positive constant (lO fcl+fc2 < q, lO* 3 < q, \0 kl+k ^ < p) 

• E : symmetric encipher function 
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" as recited in independent claim 30. 

Another feature of the present invention, as recited in independent 
claim 30, includes a ciphertext generation and transmission step of selecting 
random numbers for key data K, calculating Ui, u 2 , e, and v, where: 

u\ = g\ r mod p, U2 — gi T mod p, e = m h r mod p, v = gi ai c T d\ ar d<i Kr mod p 

Cramer does not disclose this feature. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 25 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used instead of the 
hash function. The calculation of v is unique to the present invention. 

For example, as described in column 7, line 56 to column 8, line 21 , 
Cramer discloses where the encryption means computes a first universal 
cipher-number ui, an encryption cipher-number e, a hash-value a, and a 
verification cipher-number v. The verification cipher-number v is based on the 
first group-number c, the third group-number d, the hash-value a, and the 
single exponent-number r. The present invention, as recited in claim 30, does 
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not rely upon a hash function, and thus, does not use a hash-value a. In this 
way, for example, Cramer is clearly different from the claimed invention. 
Specifically, the verification cipher-number v, as calculated in Cramer (i.e., v = 
d d a ) is quite different from v, as calculated in the present invention (i.e., v = 
g° 1 c r dr ar d 2 Kr mod p), and the Examiner has not provided any explanation as 
to why one of ordinary skill in the art would be motivated to modify Cramer to 
obtain this feature. 

By way of further example, as shown in column 8, line 5, Cramer 
discloses the formulas used for calculating ui, U2, e, and v. As shown, 
Cramer does not disclose the use of modulo arithmetic in the equations used 
to calculate Ui, u 2 , e, and v. This is quite different from the present invention, 
where the step of generating a public key includes where the elements ui, u 2 , 
e, and v are calculated using modulo arithmetic. Accordingly, Cramer does 
not teach generating a public key in the manner claimed, and the Examiner 
has not provided any explanation as to why one of ordinary skill in the art 
would be motivated to modify Cramer to obtain this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest the use of modulo arithmetic in the equations used to calculate ui, u 2 , 
e, and v, the Examiner does not provide any arguments for claim 30. 
However, as best can be determined, with reference to the Examiner's 
response regarding claim 23 on page 27 of the Examiner's Answer, it appears 
that the Examiner's position is that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). Specifically, the 
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Examiner asserts that adding, subtracting, raising to the power, or performing 
a mod operation without clearly defining what the numbers are do not 
patentably distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers a = en || a? f|ai| = ki, |a?| 
= k ? ) for key data K (IKI = ki where |x| is the number of digits of x). calculating: 

m =a\\K 

selecting a random number r^Zg, calculating: 

"l = 5i r mod p, U2 = 92 r mod p, e = m h r mod p, v = gi ai c T d\ ar d2 Kr mod p 

and generating a ciphertext C of transmission data by: 
C = E K {m) 

bv using a (symmetric) cryptographic function E and the key data K, and 
transmitting (ui, u?, e, v, C) as the ciphertext " as recited in independent claim 
30. 
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Yet another feature of the present invention, as recited in independent 
claim 30, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step is performed of executing a decipher 
process, if the following is satisfied: 

g 1 a 'iu 1 Xl+a ' yii+K ' V2 *u 2 X2+a ' vl1+K ' VM s v (mod p) 

If the above condition is not satisfied, then a. step is performed of outputting, 
as the decipher results, the effect that the received ciphertext is rejected. 
Cramer does not disclose this feature. 

In response to Appellants arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 11; and column 11, lines 43-60). The Examiner further 
asserts that adding, subtracting, raising to the power, or performing a mod 
operation without clearly defining what the numbers are do not patentably 
distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 
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For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u^ +y1a \f 2+ v 2a = v . The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciphertext and bv using the 
secret key. aY o' ? . K' (laM = ki. lo'?l = k?. IK'I = k£ which satisfy: 

<x'i\\a' 2 \\K' = e/u x z mod p 
and if the following is satisfied: 

g 1 a iui Xl + a ' Vu+K ' Vil u 2 Xi+a ' yi:i+K ' V32 = v (mod p) 

where a' = a'i II a'?, 

executing a decipher process by: 

m - D K '(C) 

outputtino deciphered results, whereas if not satisfied, outputtino as the 
decipher results the effect that the received ciphertext is rejected " as recited in 
independent claim 30. 

v. Independent Claim 35 
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One feature of the present invention, as recited in independent claim 
35, includes a ciphertext generation and transmission step of selecting 
random numbers, calculating ui, u 2 , v, and K, where: 

v = g 1 a1 c r cf r ,and K = H(h r ) . 
Cramer does not disclose this feature. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 30 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used to calculate v. 
That is to say, the calculation of v is unique to the present invention. For 
example, unlike the present invention, Cramer does not rely upon g° 1 in the 
calculation of v. In this way, for example, Cramer is clearly different from the 
claimed invention. Specifically, the verification cipher-number v, as calculated 
in Cramer (i.e., v = c r d ra ) is quite different from v, as calculated in the present 
invention (i.e., v = g° 1 d <f), and the Examiner has not provided any 
explanation as to why one of ordinary skill in the art would be motivated to 
modify Cramer to obtain this feature. 
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In response to the Examiner's arguments that as loosely defined, K can 
be interpreted as a hash value, Applicants submit that the calculation of K is 
not the same as the calculation of v. Specifically, the verification cipher- 
number v, as calculated in Cramer (i.e., v = cf d a ) is quite different from v, as 
calculated in the present invention (i.e., v = g° 1 c r cf"). Cramer uses a hash 
value in its calculation, and the present invention does not use such value in 
its calculation of v. The present invention distinguishes over Cramer in what 
is used instead of the hash value in its calculation of v. Therefore, the present 
invention is not the same as Cramer. 

Therefore, Cramer fails to teach or suggest " a ciohertext generation 
and transmission step of selecting random numbers Qi p Xi. Qp p Xp. r e- 
calculating: 

ui= gi r , u 2 = g 2 r , v = 9fc T d? r , K = H(h r ) 

where g = gj II o?. genera ting a ciohertext C of transmission data m bv 

C = EK(Tr(ati,ot2,m)) 

by using a (symmetric) cryptographic function E; and transmitting (u 1t u?, v, C) 
as the ciphertext " as recited in independent claim 35. 

Another feature of the present invention, as recited in independent 
claim 35, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step of outputting m' as the deciphered 
results if the following is satisfied: 
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g 1 a iUi Xi+Q ' yi U 2 X2+a ' V2 = V, 

If the above condition is not satisfied, then a step of outputting as the decipher 
results the effect that the received ciphertext is rejected. Cramer does not 
disclose this feature. To support the assertion that Cramer teaches this 
feature, the Examiner cites columns 9-1 1 . However, neither the cited text nor 
any other portions of Cramer, teach or suggest the claimed features. 

In response to Appellants' arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer (with reference to the rejection of claim 23) that 
Cramer expressly teaches performing calculations with the specific elements 
to obtain keys and decrypted data (citing claims 1 and 1 1 ; and column 1 1 , 
lines 43-60). The Examiner further asserts that adding, subtracting, raising to 
the power, or performing a mod operation without clearly defining what the 
numbers are do not patentably distinguish the present invention over the 
Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 
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For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u* 1+y1a u* 2+y2a = v. The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating: 

K' = H(ui") 

bv using the secret kev. calculating from the received ciphertext. g\, a'? 
(where q'i p Xi a'^X?) which satisfy: 

n(a' 1 ,a' 2 ,m') = D KI (C) 

if the following is satisfied: 

g 1 a 'iUi Xl+a ' yi U2 X3+a ' V2 = v, 

where o' = g'i II o'? 

outputting m' as the deciphered results, whereas if not satisfied, outputtino as 
the decipher results the effect that the received ciphertext is rejected " as 
recited in independent claim 35. 

vi. Independent Claim 36 

On page 31 of the Examiner's Answer, the Examiner provides a 
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response to an argument that the present invention "uses 2 more elements 
than Cramer". In response to the Examiner, Appellants respectfully submit 
that this argument was not made with regard to claim 36. 

One feature of the present invention, as recited in independent claim 
36, includes a ciphertext generation and transmission step of selecting 
random numbers, calculating ui, u 2 , v, and K, where: 

m = <7i r mod p, U2 = 92 r mod p, v = gi ai c r d ar mod p, K = H(h r mod p) 

Cramer does not disclose this feature. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 25 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used instead of the 
hash function. That is to say, the calculation of v is unique to the present 
invention. Specifically, the verification cipher-number v, as calculated in 
Cramer (i.e., v = c r d a ) is quite different from v, as calculated in the present 
invention (i.e., v = g° 1 c r <f r mod p), and the Examiner has not provided any 
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explanation as to why one of ordinary skill in the art would be motivated to 
modify Cramer to obtain this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest the use of modulo arithmetic in the equations used to calculate Ui, u 2 , 
v, and K, the Examiner asserts on page 31 of the Examiner's Answer that 
Cramer expressly teaches performing calculations with the specific elements 
to obtain keys and decrypted data (citing claims 1 and 11; and column 1 1 , 
lines 43-60). Specifically, the Examiner asserts that adding, subtracting, 
raising to the power, or performing a mod operation without clearly defining 
what the numbers are do not patentably distinguish the present invention over 
the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as shown in column 8, line 5, Cramer discloses the 
formulas used for calculating ui, u 2 , e, and v. As shown, Cramer does not 
disclose the use of modulo arithmetic in the equations used to calculate in, u 2 , 
e, v. This is quite different from the present invention, where the step of 
generating a public key includes where the elements Ui, u 2 , v, and K are 
calculated using modulo arithmetic. Accordingly, Cramer does not teach 
generating a public key in the manner claimed, and the Examiner has not 
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provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers a = ai II a? (Ichl = ki. Ia?l 
= k?, where (Ixl is the number of digits of x). selecting a random number r^Zg, 
calculating: 

ui = gi r mod p, = gi mod p, v = gi ai c r d ar mod p, K = H(h T mod p) 

transmitting the ciphertext (ui, u?. v, C): generating a ciphertext C of 
transmission data m bv: 

C = £jc(ai||a 2 ||m) 

by using a (symmetric) cryptographic function, and transmitting (ui. u ? . v. C) 
as the ciphertext " as recited in independent claim 36. 

Another feature of the present invention, as recited in independent 
claim 36, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step of outputting m' as the deciphered 
results if the following is satisfied: 

g 1 Q ^Ul Il+a ' , ' 1 ^t2 X2+Q ' V!, = v (mod p) 

If the above condition is not satisfied, then a step of outputting as the decipher 
results the effect that the received ciphertext is rejected. Cramer does not 
disclose this feature. To support the assertion that Cramer teaches this 
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feature, the Examiner cites columns 9-11. However, neither the cited text nor 
any other portions of Cramer teach or suggest the claimed features. 

In response to Appellants' arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer that Cramer expressly teaches performing 
calculations with the specific elements to obtain keys and decrypted data 
(citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). The Examiner further 
asserts that adding, subtracting, raising to the power, or performing a mod 
operation without clearly defining what the numbers are do not patentably 
distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u* 1+y1a u* 2+y2a = v. The condition [1 ] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating: 
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K' = H{ Ul z mod p) 

bv using the secret key, calculating from the received ciphertext, a'i. a'? (laM 
= ki. Ia'?l = k?) which satisfy: 

ai||a' 2 ||m' = D K ,{C) 

and if the following is satisfied: 

0i°'iui Il+a ' l ' 1 U2 I3+Q ' V2 = v (mod p) 

outputtino m ' as the deciphered results (where a 1 = a'i II a'?), whereas if not 
satisfied, outouttino as the decipher results the effect that the received 
ciphertext is rejected " as recited in independent claim 36. 

vii. Independent Claim 40 

One feature of the present invention, as recited in independent claim 
40, includes a ciphertext generation and transmission step of selecting 
random numbers, calculating Ui, u 2 and v, where: 

v = g 1 a1 c r (f r . 
Cramer does not disclose this feature. 

On page 32 of the Examiner's Answer, the Examiner provides a 
response to an argument that the present invention "Cramer does not 
expressly teach 'transmitting Ui, u 2 , e, and v'". In response to the Examiner, 
Appellants respectfully submit that this argument was not made with regard to 
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claim 40. To the contrary, Appellants argued that the calculation of v, in the 
present invention, is different from the calculation of v, as in Cramer. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function in the calculation of v, and thus, does not use a 
hash-value a, as in Cramer, the Examiner asserts on page 25 of the 
Examiner's Answer that Cramer teaches that the use of a hash function can 
be omitted (citing column 9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
present invention is different from Cramer in the feature used instead of the 
hash function. That is to say, the calculation of v is unique to the present 
invention. Specifically, the verification cipher-number v, as calculated in 
Cramer (i.e., v = d d a ) is quite different from v, as calculated in the present 
invention (i.e., v = g° 1 d cf"), and the Examiner has not provided any 
explanation as to why one of ordinary skill in the art would be motivated to 
modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers QipXi. o ?fl X?. r^Za. 
calculating: 

= g\, u 2 = 92 r y v = g 1 ai c r d ar 

where a = cm II a?, generating a c iphertext C of transmission data m bv: 
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e = E P k(7r{aii,a2,m)) 

bv using an (asymmetric) cryptographic function E pk . and transmitting (ui. u?, 
e. v) as the ciphertext " as recited in independent claim 40. 

Another feature of the present invention, as recited in independent 
claim 40, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step of outputting m' as the deciphered 
results if the following is satisfied: 

g 1 Q 'i Ul Xl+a ' yi U2 X2+a ' V2 = V, 

If the above condition is not satisfied, then a step of outputting as the decipher 
results the effect that the received ciphertext is rejected. Cramer does not 
disclose this feature. 

In response to Appellants' arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer (with regard to the rejection of claim 23) that Cramer 
expressly teaches performing calculations with the specific elements to obtain 
keys and decrypted data (citing claims 1 and 1 1 ; and column 1 1 , lines 43-60). 
The Examiner further asserts that adding, subtracting, raising to the power, or 
performing a mod operation without clearly defining what the numbers are do 
not patentably distinguish the present invention over the Cramer reference. 
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In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u, x,+y ' a if 2+y2a = v. The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciphertext and by using the 
secret key. aV a'?, m' (o'i p Xi. q' ? p X?. m' p M) which satisfy: 

TT(a[,a' 2 ,m') = D ak (e) 
and if the following is satisfied: 

g 1 a iUl Xl+a ' V1 U 2 X2+Q ' y2 = V 

where: 

a' = a\\\a' 2 
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outputtina m' as the deciphered results, whereas if not satisf ied, outouttina as 
the decipher results the effect that the received ciphertext is rejected" as 
recited in independent claim 40. 

vii. independent Claim 41 

On page 41 of the Examiner's Answer, the Examiner provides a 
response to an argument that the present invention "uses 2 more elements 
than Cramer". In response to the Examiner, Appellants respectfully submit 
that this argument was not made with regard to claim 41 . 

One feature of the present invention, as recited in independent claim 
41, includes a ciphertext generation and transmission step of selecting 
random numbers, calculating ui, u 2 and v, where: 

ui --- g± r mod p, u-2. = <?2 r mod p, v = g\ ax c T <$ xr mod p 
Cramer does not disclose this feature. 

In response to Appellants' arguments that the present invention 
distinguishes over Cramer because unlike Cramer, the present invention does 
not rely upon a hash function, and thus, does not use a hash-value a, as in 
Cramer, the Examiner asserts on page 25 of the Examiner's Answer that 
Cramer teaches that the use of a hash function can be omitted (citing column 
9, lines 60-67). 

In response to the Examiner's arguments, Appellants acknowledge that 
Cramer teaches where the hash function can be omitted. However, the 
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present invention is different from Cramer in the feature used instead of the 
hash function. That is to say, the calculation of v is unique to the present 
invention. Specifically, the verification cipher-number v, as calculated in 
Cramer (i.e., v = d d a ) is quite different from v, as calculated in the present 
invention (i.e., v = g° 1 d <f r mod p), and the Examiner has not provided any 
explanation as to why one of ordinary skill in the art would be motivated to 
modify Cramer to obtain this feature. 

In response to Appellants' arguments that Cramer does not teach or 
suggest the use of modulo arithmetic in the calculation of Ui, u 2 and v, the 
Examiner asserts that Cramer provides the teachings of using modulo 
arithmetic to generate the verification value (citing column 7, lines 60-67 and 
column 8, lines 1-10). 

In response to the Examiner's arguments, Appellants submit that 
column 7, lines 60-67 to column 8, lines 1-10 refer to the modulo of element q. 
Specifically, Cramer discloses where a single exponent-number r is chose at 
random in an r-choosing step from a set of elements modulo q, denoted as Z q . 
This use of modulo arithmetic in Cramer is not the same as the use of modulo 
arithmetic in the calculation of ui, u 2 and v, in the manner claimed. 

For example, as shown in column 8, line 5, Cramer discloses the 
formulas used for calculating ui, u 2 and v. As shown, Cramer does not 
disclose the use of modulo arithmetic in the equations used to calculate m, u 2 
and v. This is quite different from the present invention, where the step of 
generating a public key includes where the elements ui, u 2 and v, are 
calculated using modulo arithmetic. Accordingly, Cramer does not teach 
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generating a public key in the manner claimed, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext generation 
and transmission step of selecting random numbers a = pi II a? (laj = ki. la?l 
= k ? . where Ixl is the number of digits of xV selecting a random number r^Zo. 
calculating: 

m - g\ r mod p, = g-i mod p, v = gi ai c r <f* r mod p 

generating a ciphertext C of transmission data m (positive integer) bv: 

e = E pk (ai\\a2\\m) 

bv using the secret kev. and transmitting (ui. u ? . e. v) as the ciphertext " as 
recited in independent claim 41 . 

Another feature of the present invention, as recited in independent 
claim 41, includes a ciphertext reception and decipher step. This step 
includes a condition, such that a step of outputting m' as the deciphered 
results if the following is satisfied: 

gi a i Ul Xl+a ' v >U2 X2 + Q ' v * = v (mod p) 

If the above condition is not satisfied, then a step of outputting as the decipher 
results the effect that the received ciphertext is rejected. Cramer does not 
disclose this feature. 
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In response to Appellants' arguments that Cramer fails to teach or 
suggest the above-identified condition, the Examiner asserts on page 27 of 
the Examiner's Answer (with regard to the rejection of claim 23) that Cramer 
expressly teaches performing calculations with the specific elements to obtain 
keys and decrypted data (citing claims 1 and 1 1 ; and column 11, lines 43-60). 
The Examiner further asserts that adding, subtracting, raising to the power, or 
performing a mod operation without clearly defining what the numbers are do 
not patentably distinguish the present invention over the Cramer reference. 

In response to the Examiner's arguments, Appellants submit that the 
elements contained in the claims are well known to one of ordinary skill in the 
art. Therefore, further defining the elements is not necessary. Furthermore, 
whether or not the terms are clearly defined, Cramer still fails to teach the 
features of the present invention, and is clearly different from the claimed 
invention. 

For example, as described in column 8, lines 50-62, Cramer discloses 
a condition [1]: u,*' +y,a t/ 2+y2a = v. The condition [1] of Cramer is not the 
same as the above-described condition of the present invention. Accordingly, 
Cramer does not disclose the claimed feature, and the Examiner has not 
provided any explanation as to why one of ordinary skill in the art would be 
motivated to modify Cramer to obtain this feature. 

Therefore, Cramer fails to teach or suggest " a ciphertext reception and 
decipher step of calculating from the received ciphertext and by using the 
secret key, aV a'?, m' (laM = ki. Ia' ? | = k?. m' is a positive integer) which 
satisfy: 
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«iM|m'=Z). fc (e) 
and if the following is satisfied: 

gi < Ul *i+<*'vi U2 x*+*'v? = v ( mod p)j 

where: 

q' = allied 

outputtina m' as the deciphered results, whereas if not satisfied, outputtinq as 
the decipher results the effect that the received ciphertext is rejected " as 
recited in independent claim 41 . 

C. Conclusion 

Therefore, based on the above remarks, Appellants submit that the 
Examiner's final rejection of claims 23-44 under 35 (JSC §112, second 
paragraph; and the rejection of claims 23-44 USC § 103(a) are not properly 
founded in law and respectfully request that the Board of Patent Appeal 
Interferences reverse the Examiner's final rejection. 
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To the extent necessary, Appellants petition for an extension of time 
under 37 CFR §1.136. Please charge any shortage in the fees due in 
connection with the filing of this paper, including extension of time fees, to 
Deposit Account No. 50-1417 (Case No. 500.41092X00) and please credit 
any excess fees to such Deposit Account. 



Respectfully submitted, 



MATTINGLY, STANGER, MALUR & BRUNDIDGE, P.C. 




Carl I. Brundidge 
Registration No. 29,621 



CIB/DKM/cmd 
(703) 684-1120 



Enclosures 
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VIII. CLAIMS APPENDIX 

The copy of the claims contained in the Appendix to the Appeal Brief is 
correct, as the Examiner affirmed in the Examiner's Answer. 

IX. EVIDENCE APPENDIX 

The statement of the evidence contained in the Appeal Brief is correct, 
as the Examiner affirmed in the Examiner's answer. 

Accordingly, there is no evidence relied upon in this Appeal. 

X. RELATED PROCEEDINGS APPENDIX 

The statement of the related proceedings contained in the Appeal Brief 
is correct, as the Examiner affirmed in the Examiner's Answer. 
Accordingly, there are no related proceedings. 

XI. FEES 

To the extent necessary, Appellants petition for an extension of time 
under 37 CFR §1.136. Please charge any shortage in the fees due in 
connection with the filing of this paper, including extension of time fees, to 
Deposit Account No. 50-1417 {Case No. 500.41092X00) and please credit 
any excess fees to such Deposit Account. 



Respectfully submitted, 



MATTINGLY, STANGER, MALUR & BRUNDIDGE, P.C. 




CIB/DKM/cmd 
(703) 684-1120 
Enclosures (in triplicate) 
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